SCIM provisioning using Microsoft Entra ID (Azure AD)

Account owners and admins can use System for Cross-Domain Identity Management (SCIM) to provision users and groups from Microsoft Entra ID (formerly Azure Active Directory) to applications automatically. For the Entra ID side, follow Microsoft's guide to provisioning users and groups with SCIM.

Requirements

  • Advanced Authentication + User Management

Robin offers a pre-configured SAML app in the Azure Marketplace.

To learn more, see Robin in the Azure Marketplace.

Generate a SCIM token in Robin

Entra ID uses this token to connect to Robin.

  1. Sign in to your Robin account dashboard: https://dashboard.robinpowered.com/login
  2. Go to Manage > Integrations.
  3. Under Add Connectors, search for Microsoft Entra ID and select Set up directory sync. You can also use the SCIM provisioning tile. It shows Manage when SCIM is already set up. The SCIM Provisioning page opens.
  4. Select Generate Token for SCIM. Robin shows the token only once.
  5. Copy the token. You paste it into the Secret Token field in Entra ID.

If you lose the token, select Revoke Token, then generate a new one and enter it in Entra ID. Provisioning stops until you do. People already in Robin stay in Robin.

Set up provisioning in Entra ID

Create an app in Entra ID, connect it to Robin with the token, and choose who to provision.

Create the app

  1. In the Microsoft Entra admin center, go to Enterprise Applications.
  2. Select New application > Create your own application > Non-gallery application.
  3. Enter a name for your application.
  4. Select Add to create an app object.

Connect the app to Robin

  1. Select Provisioning in the left column.
  2. In the Provisioning Mode menu, select Automatic. The Admin Credentials section opens.
  3. In the Tenant URL field, enter the URL of the application's SCIM endpoint:

    https://api.robinpowered.com/v1.0/scim-2
  4. In the Secret Token field, paste the token you generated in Robin.
  5. To check the connection, select Test Connection.
  6. Under Settings, set the Scope to Sync only assigned users and groups.

The Provisioning page in Microsoft Entra ID with Automatic mode, the Tenant URL and Secret Token fields, and the Scope setting

Assign people and start provisioning

  1. In the left menu, under Manage, select Users and Groups.
  2. Add the users and groups you want to provision to Robin.
  3. In the Provisioning tab, select Start Provisioning.

Users should appear in your Robin account within a few minutes.

User attribute mapping

The preconfigured app does not support the department attribute.

Robin requests these User attributes. Each Robin attribute maps from an Entra ID attribute. Robin uses the work email as the person's email address in Robin, so map it from mail, the person's mailbox address. Do not map it from userPrincipalName: the sign-in name can differ from the mailbox address.

Robin attribute Entra ID attribute Matching precedence
userName userPrincipalName 1
emails[type eq "work"].value mail
externalId objectId 2
active Switch([IsSoftDeleted], , "False", "True", "True", "False")
displayName displayName
title jobTitle
name.givenName givenName
name.familyName surname
name.formatted Join(" ", [givenName], [surname])
urn:ietf:params:scim:schemas:extension:enterprise:2.0:User:department department
urn:ietf:params:scim:schemas:extension:enterprise:2.0:User:manager manager

Turn on the Create, Update and Delete target object actions.

These Optional user attributes are also available:

  • department
  • costCenter
  • division
  • employeeNumber
  • locale
  • title
  • manager
  • preferredLanguage

To sync optional attributes, create a new attribute mapping, choose the fields and set the correct schema. For example, to sync department, select Add New Mapping and map the Entra ID attribute department to urn:ietf:params:scim:schemas:extension:enterprise:2.0:User:department. Use these schemas:

  • For title, locale or preferredLanguage, use the core user schema, urn:ietf:params:scim:schemas:core:2.0:User.
  • For department, costCenter, division, employeeNumber or manager, use the enterprise user schema, urn:ietf:params:scim:schemas:extension:enterprise:2.0:User.

Group attribute mapping

Set up the group attribute mapping in Entra ID, with the Create, Update and Delete target object actions turned on. Robin requests these Group attributes. Each Robin attribute maps from an Entra ID attribute:

Robin attribute Entra ID attribute Matching precedence
displayName displayName 1
externalId objectId
members members
The group attribute mappings in Microsoft Entra ID: displayName, externalId and members

Sync managers

To sync managers into Robin, add the manager attribute to the mappings. Its value should match the manager's externalId in Entra ID.

For example, UserA has the Entra ID 3cd19cd0-ba07-4171-86db-50d8d7694e19, and UserB has the Entra ID 01972a50-2801-4f06-a403-b41f9f04206e. To make UserA the manager of UserB, set the manager field of UserB to 3cd19cd0-ba07-4171-86db-50d8d7694e19. This value is UserA’s Entra ID.

You find the Entra ID in the user’s profile in Entra ID, under Overview > Object ID.

Entra ID must send each user’s Entra ID as externalId. The manager must also be provisioned to Robin through SCIM, in the same Robin organization.

Robin links managers every 3 hours. It links only people whose record changed since the previous evening. If you add the manager later, change any attribute on the employee so your identity provider sends an update. Robin then links the manager.

Articles in this section

Was this article helpful?
19 out of 46 found this helpful
Share